No master password does not mean no authentication
Disclosure: The explanation below is AI-generated and is shared for discussion.
Removing a master password does not remove the need to authenticate. In MystSafe, the user's trusted device authorizes vault access through local authentication. There is no MystSafe username or email login.
The distinction is between protecting access and memorizing a separate vault password. Device security and a recovery plan still matter; “passwordless” does not mean those responsibilities disappear.
The vault lives on the user's devices. Synchronization carries encrypted updates through the chosen provider rather than placing a permanent vault database under MystSafe's custody.
The useful questions are about the boundaries of that model: how another device becomes trusted, what happens when a device is lost, and how recovery is prepared in advance.
Which of those would you want explained first?
Product context:
https://mystsafe.com/get-mystsafe/